PageFair anti-ad-blocking service was hacked a week ago, temporarily pushing malware to visitors of over 500 sites including the Economist
On Oct. 31, 2015, one of economist.com's vendors, PageFair, was hacked. Nelson Minar / Nelson's Weblog : PageFair serves malware on the Economist Dan Goodin / Ars Technica : Hackers use anti-adblocking service to deliver nasty malware attack AdExchanger : As Ad Blocking Grows, What Legal Recourse Do Publishers And Marketers Have? Shaun Nichols / The Register : Read the Economist last weekend? You may have fetched more than just articles (yup, malware) Adrian Bridgwater / SC Magazine UK : PageFair adblocking site ‘recovers’ from Halloween hack in 83 minutes Jessica Davies / Digiday : 500 publishers were hacked through anti-ad block tool PageFair Chris Brook / Threatpost : PageFair Hack Serves Up Fake Flash Update to 500 Sites Alexander J Martin / The Register : Anti-adblocker firm PageFair's users hit by fake Flash update Charlie Osborne / ZDNet : Anti ad-block firm PageFair becomes cyberattack victim, distributes malware Tweets: Dan Gillmor / @dangillmor : Inadequately, the @economist says “sorry for the inconvenience” after its anti-ad-blocker partner served malware. http://www.economist.com/... @malwrhunterteam : “1. Change passwords...3. Run AV” http://www.economist.com/... The order of steps are wrong. Firstly remove the malware, then change passwords... @pinboard : A nice 7 MB ad-stuffed page from the Economist explaining how you may have been hacked by one of their earlier ads http://www.economist.com/... @pagefair : Update 8 - 92.5% of people with antivirus are now immune to the trojan used in the halloween hacking incident. http://blog.pagefair.com/... @pagefair : Update 7: Any website visitors who installed the malicious program are now safe from being controlled by the hacker. http://blog.pagefair.com/... See also Mediagazer
Context & Ripple Effects
Publishers fighting ad blockers have been outsourcing the fight: PageFair built a business measuring and countering blocked ads, and its script ran on hundreds of publisher domains including economist.com. That made it exactly the kind of quiet third-party dependency whose compromise propagates everywhere at once — which is what happened when it was hacked on Oct. 31 and briefly served malware to visitors of more than 500 sites.
The incident lands mid-boom in the counter-ad-blocking market: vendors are raising money to push past blockers (Admiral recently raised $2.5M for circumvention tools), and later code analysis would find nearly a third of the Alexa top 10K running such measures, many hidden from their own visitors. Every one of those deployments widens the same attack surface this breach just demonstrated.
First-order effects
- Visitors to over 500 publisher sites — The Economist most prominently — were exposed to malware served through the compromised PageFair script during the intrusion window, before the service was restored within roughly 83 minutes per SC Magazine's coverage.
- PageFair's core pitch to publishers — recover ad revenue safely — is directly damaged: its customers now have to weigh whether the countermeasure itself is the bigger risk to readers.
Second-order effects
- Rival anti-ad-blocking vendors like Admiral inherit the trust burden: publishers evaluating circumvention contracts will demand security assurances and liability terms that didn't exist before a peer vendor became a malware vector.
- Ad-tech suppliers generally get pulled into publishers' vendor-risk reviews alongside analytics and tag managers, since any injected script with sitewide reach can now be framed as a potential distribution channel for attacks — the same bundling dynamic behind the adware-driven malware growth McAfee documented.
Third-order effects
- If silent anti-ad-blocking keeps spreading — the trajectory from PageFair's niche tooling toward 30.5% of top sites suggests it does — the industry converges on a handful of shared countermeasure scripts, meaning a single compromise can touch a large share of the web's ad inventory at once; regulators and security teams will increasingly treat these scripts as critical infrastructure rather than marketing add-ons.
The trend: Anti-ad-blocking is consolidating into shared third-party infrastructure, concentrating both publishers' revenue recovery and their security exposure in a few vendors whose breaches cascade across hundreds of sites at once.